VYPR
Vendor

Crafthemes

Products
8
CVEs
10
Across products
18
Status
Private

Products

8

Recent CVEs

10
  • CVE-2019-20209HigJan 13, 2020
    risk 0.49cvss 7.5epss 0.03

    The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow nsecure Direct Object Reference (IDOR) via wp-admin/admin-ajax.php to delete any page/post/listing.

  • CVE-2023-36502HigJul 25, 2023
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cththemes Balkon plugin <= 1.3.2 versions.

  • CVE-2023-29430HigJun 26, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CTHthemes TheRoof theme <= 1.0.3 versions.

  • CVE-2023-29236HigApr 7, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Outdoor theme <= 3.9.6 versions.

  • CVE-2023-25041HigApr 7, 2023
    risk 0.46cvss 7.1epss 0.00

    Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Cththemes Monolit theme <= 2.0.6 versions.

  • CVE-2024-5092MedMay 22, 2024
    risk 0.42cvss 6.4epss 0.00

    The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Switcher, Slider, and Iconbox widgets in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping on user supplied…

  • CVE-2024-3066MedMay 22, 2024
    risk 0.42cvss 6.4epss 0.00

    The Elegant Addons for elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping on user supplied tag attributes. This makes it…

  • CVE-2019-20212MedJan 13, 2020
    risk 0.40cvss 6.1epss 0.03

    The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via the chat widget/page message form.

  • CVE-2019-20211MedJan 13, 2020
    risk 0.40cvss 6.1epss 0.03

    The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Persistent XSS via Listing Address, Listing Latitude, Listing Longitude, Email Address, Description, Name, Job or Position, Description, Service Name, Address,…

  • CVE-2019-20210MedJan 13, 2020
    risk 0.40cvss 6.1epss 0.03

    The CTHthemes CityBook before 2.3.4, TownHub before 1.0.6, and EasyBook before 1.2.2 themes for WordPress allow Reflected XSS via a search query.